MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b2f1be017febaeb469d504f110ee6b1a4d1b5202115ad8b7b22f6a4901e20b91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b2f1be017febaeb469d504f110ee6b1a4d1b5202115ad8b7b22f6a4901e20b91
SHA3-384 hash: 0277bac444554ee9f3567d4012931799113ed44ff0b682591ff031325f9bbcf23ebeac869087d32574b2dd566bc9741a
SHA1 hash: 3e4b2fb5907f2959e25e351ba50ab711f2217de3
MD5 hash: 1c762ddd52351b45545eb9c03ce54c78
humanhash: king-single-carpet-sink
File name:order pdf.zip
Download: download sample
Signature FormBook
File size:318'634 bytes
First seen:2020-06-08 06:49:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:89RC8kwmrgaVsHn8yJc0spaNUUcRiabQWewNyVvV68TPipmUtWbH5m:89/kuaOH8pYSieeEy9g8LEmNo
TLSH 526423A1203E88E5C152F2976D7755CC0A964B906148AC7F76A4FF4DBEA9083F41EBF0
Reporter abuse_ch
Tags:FormBook zip


Avatar
abuse_ch
Malspam distributing FormBook:

HELO: mx2.telrad.net
Sending IP: 77.239.64.29
From: asia <contact@bdg-asia.com>
Subject: Re
Attachment: order pdf.zip (contains "order pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Malrep
Status:
Malicious
First seen:
2020-06-08 05:01:34 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

FormBook

zip b2f1be017febaeb469d504f110ee6b1a4d1b5202115ad8b7b22f6a4901e20b91

(this sample)

  
Dropping
FormBook
  
Delivery method
Distributed via e-mail attachment

Comments